A vulnerability classified as problematic has been found in Zimbra Collaboration up to 10.1.16 . The impacted element is the function Forward servlet of the file WEB-INF/web.xml of the component Classic Web Client . This manipulation of the argument fu causes file inclusion. This vulnerability is registered as CVE-2026-73574 . Remote exploitation of the attack is possible. No exploit is available. It is recommended to upgrade the affected component.